.312 Vulnerabilities
Does anyone know if these issues still exist?
1.A vulnerability has been identified in Audacity, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when importing a GRO file containing overly long data, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into importing a malicious ".GRO" file.
2. A vulnerability has been identified in Audacity, which could be exploited by local attackers to bypass security restrictions and cause a denial of service. This issue is caused by an error when creating and handling temporary files, which could allow malicious users to conduct symlink attacks and delete arbitrary files and directories with the privileges of the user invoking the vulnerable script, creating a denial of service condition
3.12 Vulnerabilities
Forum rules
Audacity 1.3.x is now obsolete. Please use the current Audacity 2.1.x version.
The final version of Audacity for Windows 98/ME is the legacy 2.0.0 version.
Audacity 1.3.x is now obsolete. Please use the current Audacity 2.1.x version.
The final version of Audacity for Windows 98/ME is the legacy 2.0.0 version.
-
Gale Andrews
- Quality Assurance
- Posts: 41761
- Joined: Fri Jul 27, 2007 12:02 am
- Operating System: Windows 10
Re: 3.12 Vulnerabilities
The current Audacity Beta is 1.3.12.hkennedy wrote:.312 Vulnerabilities
If you are referring to http://www.vupen.com/english/advisories ... references that is claimed to apply to 1.2.6. The 1.2.6 version is no longer being developed. Are you able to replicate this in 1.3.12?hkennedy wrote: 1.A vulnerability has been identified in Audacity, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when importing a GRO file containing overly long data, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into importing a malicious ".GRO" file.
If you are referring to http://www.vupen.com/english/advisories/2007/4025 and this is the same issue as CVE-2007-6061, then this was fixed in Audacity 1.3.5.hkennedy wrote:2. A vulnerability has been identified in Audacity, which could be exploited by local attackers to bypass security restrictions and cause a denial of service. This issue is caused by an error when creating and handling temporary files, which could allow malicious users to conduct symlink attacks and delete arbitrary files and directories with the privileges of the user invoking the vulnerable script, creating a denial of service condition
Gale
________________________________________FOR INSTANT HELP: (Click on Link below)
* * * * * Tips * * * * * Tutorials * * * * * Quick Start Guide * * * * * Audacity Manual
* * * * * Tips * * * * * Tutorials * * * * * Quick Start Guide * * * * * Audacity Manual
Re: 3.12 Vulnerabilities
how can this happen if you are not online?
who runs internet at the same time as audio software ??
dont do that !!
can this happen from a previous drive by download ???
who runs internet without a firewall and antivirus and registry guard ??
what is the mechanism that audacity could be exploited ?
i understand how pdf and jpeg and some others could occur.
who runs internet at the same time as audio software ??
dont do that !!
can this happen from a previous drive by download ???
who runs internet without a firewall and antivirus and registry guard ??
what is the mechanism that audacity could be exploited ?
i understand how pdf and jpeg and some others could occur.
-
Gale Andrews
- Quality Assurance
- Posts: 41761
- Joined: Fri Jul 27, 2007 12:02 am
- Operating System: Windows 10
Re: 3.12 Vulnerabilities
Just about anyone with a broadband internet connection controlled by a router (i.e no explicit dial up by the user). It's quite a few steps to disconnect that.whomper wrote:who runs internet at the same time as audio software ??
Gale
________________________________________FOR INSTANT HELP: (Click on Link below)
* * * * * Tips * * * * * Tutorials * * * * * Quick Start Guide * * * * * Audacity Manual
* * * * * Tips * * * * * Tutorials * * * * * Quick Start Guide * * * * * Audacity Manual
Re: 3.12 Vulnerabilities
score one for dial up users
i was taught to disconnect from broadband when not needed to avoid such problems
i was taught to disconnect from broadband when not needed to avoid such problems
Re: 3.12 Vulnerabilities
The Vulnerabilities were identified in a security scan of the last version. I wanted to know if they exist in the beta version. Thank you for the info.
Re: 3.12 Vulnerabilities
Audacity 1.3.12 is the "last" version.
Which version have you done a "security scan" with, and how did you do the security scan?
You can find the Audacity version number by looking in the Audacity "Help menu > About Audacity".
Which version have you done a "security scan" with, and how did you do the security scan?
You can find the Audacity version number by looking in the Audacity "Help menu > About Audacity".
9/10 questions are answered in the FREQUENTLY ASKED QUESTIONS (FAQ)